tracelens-analysis-orchestrator

Warn

Audited by Socket on Aug 16, 2026

1 alert found:

Security
SecurityMEDIUM
evals/evals.py

This module is not overtly malicious in itself, but it creates a high-risk supply-chain execution pathway: it downloads and editable-installs a repository from an environment-controlled URL, extracts a tarball using `tar.extractall` without path validation, and executes the repository’s evaluation scripts via subprocess. If an attacker can influence TRACELENS_* environment variables or the cloned repository/tarball content, the most likely impact is arbitrary code execution and/or filesystem manipulation (including possible tar path traversal/symlink escape).

Confidence: 74%Severity: 77%
Audit Metadata
Analyzed At
Aug 16, 2026, 01:20 AM
Package URL
pkg:socket/skills-sh/amd%2Fskills%2Ftracelens-analysis-orchestrator%2F@2afb6d118b8c05af5d47ff772608eb78b0abb1e47c7e832314d573dcec50881e
Security Audit — socket — tracelens-analysis-orchestrator